Incident Response & Ransomware Recovery
Digital Forensics and Investigation
Forensics answers questions that carry consequences: what did this person take, how long was the attacker inside, was personal data accessed. Because those answers get used in disciplinary hearings, regulatory filings and courtrooms, how the evidence was acquired matters as much as what it shows. Every step is documented, hashed and defensible.
Methodology
- 01
Scoping and legal context
What question the investigation must answer, who commissioned it, and whether findings may be used in disciplinary, regulatory or legal proceedings — which determines the evidential standard from the first action.
- 02
Evidence identification and preservation
Systems, accounts, cloud tenants and devices in scope, with preservation notices and litigation holds applied before anything can be overwritten.
- 03
Forensic acquisition
Write-blocked disk imaging, memory capture and cloud log export, each hashed at acquisition and verified, with chain of custody documented from that moment.
- 04
Timeline construction
File system, registry, event log, browser and application artefacts correlated into a single timeline across all sources.
- 05
Artefact analysis
Execution evidence, file access, USB device history, cloud sync, email activity and deleted file recovery, according to the question being answered.
- 06
Data movement analysis
What was copied, to where, and when — removable media, cloud storage, personal email and messaging platforms.
- 07
Attribution and corroboration
Findings corroborated across independent artefact sources, because a single artefact is rarely sufficient to support a conclusion someone will contest.
- 08
Reporting and testimony
A report written to be understood by a non-technical reader and to withstand challenge, with expert testimony available where proceedings require it.
Approach to testing
- Evidential standard from the first action, because it cannot be applied retrospectively. If there is any possibility of proceedings, acquisition is done properly the first time.
- Findings are corroborated across independent artefacts. A single registry key is an indication; three independent artefacts agreeing is a finding.
- Confidence is stated explicitly. 'The file was copied to a USB device' and 'a USB device was connected and the file was accessed in the same period' are different claims, and the report distinguishes them.
- Absence of evidence is reported as such. Logs that were not retained, or artefacts overwritten before preservation, are stated plainly rather than papered over with inference.
- The investigator is independent of the outcome. CSS reports what the evidence shows, including where it does not support the commissioning party's expectation.
Types of assessment
Incident forensics (default)
Establishing how an intrusion occurred, its extent and what was accessed. Usually follows or accompanies incident response.
Insider investigation
Data theft, policy violation or misconduct by an employee. Requires particular care over scope, privacy and employment law.
Data breach scope determination
Establishing exactly what personal data was accessed, to support a notification decision that regulators will scrutinise.
Litigation support and eDiscovery
Evidence preservation, collection and analysis for civil proceedings, with expert testimony where required.
Frameworks and standards
- ISO/IEC 27037
- Identification, collection, acquisition and preservation of digital evidence — the acquisition standard followed.
- ISO/IEC 27041 / 27042
- Assurance of investigation methods, and analysis and interpretation of evidence.
- NIST SP 800-86
- Integrating forensic techniques into incident response.
- ACPO / equivalent good practice guides
- Principles for handling digital evidence, particularly around preserving original media.
- Indian Evidence Act and IT Act provisions
- Where findings may be used in Indian legal proceedings, including Section 65B certification requirements.
Tools used
Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.
FTK Imager / dd with write blockers
Forensically sound acquisition with hash verification at capture.
Autopsy / X-Ways
File system analysis, deleted file recovery and artefact extraction.
Volatility
Memory analysis for process, network and injected code evidence.
Plaso / Timesketch
Super-timeline construction across all artefact sources.
KAPE
Targeted artefact collection where full imaging is impractical.
Cloud audit log tooling
Microsoft 365, Google Workspace and cloud provider log acquisition and analysis.
Hashing and chain of custody tooling
Documented custody records from acquisition to reporting.
Checklist approach
The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.
Acquisition
- Write-blocked or verified read-only acquisition
- Hash calculated at acquisition and verified after transfer
- Memory captured before power-down where the system is live
- Cloud logs exported within their retention window
- Chain of custody documented from first contact
- Preservation notice issued to prevent overwriting
System artefacts
- Program execution: prefetch, shimcache, amcache, userassist
- File access and Most Recently Used artefacts
- Event logs including deletion and clearing events
- Registry hives and their transaction logs
- Scheduled tasks, services and persistence
- Volume shadow copies and their contents
Data movement
- USB and removable media connection history
- Files copied to removable media
- Cloud sync client activity and uploaded content
- Personal webmail and messaging platform usage
- Print history
- Archive creation preceding transfer
Account and access
- Authentication history across systems and cloud
- Privilege changes and group membership modifications
- Remote access sessions and their source
- Mailbox rules, delegation and forwarding
- OAuth grants and application access
Evidential integrity
- Every finding corroborated across independent artefacts
- Confidence stated per finding
- Gaps in evidence documented explicitly
- Analysis reproducible from the preserved images
- Section 65B or equivalent certification where required
How findings are scored
Every finding is scored on CVSS 3.1 and placed in one of five levels. The executive summary adds a sixth band — Compliant — so components that passed appear on the same chart as those that did not.
- Critical
- Immediate measures must be taken. These vulnerabilities can allow an attacker to take complete control of the application or server — stealing user data, tricking users into supplying sensitive information, or defacing the site.
- High
- Maximum risk associated with a specific vulnerability instance. May enable an attacker to compromise the application and its data, partially or completely, or to modify application behaviour beyond its intended purpose. To be handled with utmost priority.
- Medium
- Considerable risk. May enable an attacker to exploit the application to a particular level, gaining low-level information that can be used to craft more specific attacks.
- Low
- Lowest risk. May allow an attacker to gain some information about the application that was not intended to be known, without an exploitation technique currently available at that instance.
- Informational
- A functionality or component is missing best-practice implementation. Not a risk today, but may become one as the application changes or as exploitation techniques, policy or legal requirements evolve.
Scan types selected
- Safe Checks
- Standard / OWASP Top 10
- Destructive
- SANS Top 25
- Business Logic Vulnerability Testing
Standard toolset by stage
- OSINT
- Datasploit, Google Dorks, Shodan
- Enumeration & Scanning
- Nmap, Wfuzz, Unicornscan
- Domain Enumeration
- Nikto, DnsRecon, Knock
- Crawling & Fuzzing
- Burp Suite, Acunetix, Netsparker
- Vulnerability Analysis
- OpenSSL, sqlmap, CVE-Details
- Exploitation
- Metasploit, Netcat, Exploit-DB
How CSS tests
A unified swarm of agents, for blind spot detection
AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.
Super-timeline construction across multiple images and log sources produces millions of events; surfacing the relevant hundred is exactly what parallel analysis is for.
Cross-artefact corroboration — confirming a single conclusion against execution, file access and USB artefacts independently — is systematic checking that manual analysis performs only for the findings an investigator already suspects.
Keyword and pattern search across terabytes of unallocated space is breadth work.
Anomaly detection across authentication logs spanning months identifies the session that matters among hundreds of thousands of normal ones.
Analysis is assisted; conclusions are not. Every finding in a forensic report is reached and asserted by a human investigator who can defend it under challenge. Agents surface candidates and correlate artefacts; an agent's output never appears in a report as a finding, because an expert witness must be able to explain how a conclusion was reached.
Why this differs
What CSS does that most vendors do not
Every one of these is checkable. Ask any vendor for the same and compare the answers.
Evidential standard from the first action
Acquisition is done to a standard that survives challenge whether or not proceedings are anticipated, because that decision cannot be revisited after the fact.
Confidence stated, gaps declared
Findings carry an explicit confidence level, and missing evidence is reported as missing rather than filled with inference. That is what makes the rest of the report credible.
Independent of the outcome
CSS reports what the evidence shows, including where it does not support the commissioning party's expectation. An investigator who finds what the client hoped for is not much use in a hearing.
Written to be understood
The report is written for a non-technical reader — an HR panel, a regulator, a judge — while remaining technically defensible. Most forensic reports fail one of those two tests.
Reporting
Two documents, two audiences
Both are produced for every engagement. They are not the same document at two lengths — they answer different questions and are written separately. The structure below is the one CSS actually issues.
Technical assessment report
For the engineers who will fix it
- Disclaimer, and Limitations on Disclosure and Use
- Risk Level & Description — the five levels above, scored on CVSS 3.1
- Scan Type — which of the five assessment types were selected
- Assessment Scope — the control areas covered
- Assessment Date — the exact testing window
- Objective of the Assessment — objectives listed against completion status
- Tools Utilization — manual and automated tooling by stage
- Summary of the Assessment
- Overall Recommendations, split into Must Have and Should Have
- Vulnerability Overall Classifications as per Organization
- Security Issues Highlighted
- The Key Findings — each with evidence and detailed recommendation
- Summary of Findings & Conclusion
For this assessment specifically
- Scope, commissioning party, questions posed and the evidential standard applied
- Evidence inventory with acquisition method, hashes and chain of custody
- Methodology, with tooling and versions, so analysis is reproducible
- Timeline of relevant events with source artefact for each
- Findings with confidence level and corroborating artefacts named
- Data movement analysis: what, where and when
- Explicit statement of evidence gaps and their cause
- Section 65B or equivalent certification where required
Executive summary
For the people who will fund the fix
- Objectives, each against a completion status
- Overall Finding of the Assessment — total threats identified, broken down by component and severity
- Summary of the Assessment
- Artefacts of the Assessment — the key findings as a numbered register with severity
- Observation of the Assessment — the major attacks the organisation should be prepared for, given what was found
- Overall Recommendation, including a Business Enabling Recommendation sequence
- Must Have and Should Have actions
For this assessment specifically
- The question asked, and the answer, in plain language
- What the evidence supports, and how confidently
- What could not be determined, and why
- Timeline in dates rather than timestamps
- Implications for notification, disciplinary or legal action
- One page
Case studies
What this finds in practice
Representative engagement patterns. Sector and scale only — no client is named, and no detail is included that could identify one.
A professional services firm investigating a departing partner suspected of taking client data.
- Finding
- USB artefacts showed a device connected three times in the final fortnight. File access artefacts showed 2,100 client documents opened in a pattern inconsistent with normal work, and a personal cloud sync client had been installed eleven days before resignation and removed two days before departure — with its installation and uninstallation both recoverable.
- Recommendation
- Findings supported the firm's position in proceedings. Separately, the absence of DLP and removable media control was reported as the reason the activity was possible.
- Outcome
- The matter was settled on the strength of the corroborated timeline. The firm implemented removable media control and cloud sync restrictions the following quarter.
A financial services firm determining breach scope after an intrusion.
- Finding
- The attacker had accessed a file server for six days. Analysis of access artefacts and server logs established exactly which directories were opened and which were not, narrowing the affected population from an assumed 40,000 records to a documented 1,340.
- Recommendation
- Notify on the basis of the documented scope, with the evidence retained to support the figure if the regulator queried it.
- Outcome
- Notification proceeded on the narrower scope. The client's counsel regarded the documented basis as the most valuable output, since an unevidenced estimate would have had to assume the larger figure.
A manufacturer investigating suspected fraud in procurement.
- Finding
- Email and file artefacts showed the suspected activity, but the critical fortnight fell outside the mailbox audit retention window, which had been set to 90 days. That evidence was unrecoverable.
- Recommendation
- Report the gap plainly rather than inferring across it, and extend audit log retention to twelve months so a future investigation is not defeated by retention settings.
- Outcome
- The investigation reached a partial conclusion, stated as such. Retention was extended across the tenant, which the client described as the finding with the most lasting value.
Next
Scope this assessment
Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.